YouTube2Text

Designing Basic Enterprise Campus Networks Part 2 — Transcript

by Santelmo · 4,905 words · 1,021 segments · language en · Watch on YouTube

Full transcript

  1. 0:04enterprise campus design
  2. 0:09as discussed in the previous video the
  3. 0:11enterprise campus functional
  4. 0:13area is divided into the following
  5. 0:15modules so
  6. 0:16first you've got the campus
  7. 0:18infrastructure
  8. 0:20this module includes three layers okay
  9. 0:23so you've got the building access layer
  10. 0:25the distribution
  11. 0:26layer and the campus core layer
  12. 0:30now you also have the server form edge
  13. 0:33distribution which is optional okay so
  14. 0:37this section discusses the design
  15. 0:40of each of the layers and modules within
  16. 0:43the enterprise campus and identifies
  17. 0:46best practices related to the design
  18. 0:49of each
  19. 0:53let's start with the relative
  20. 0:55considerations for the campus design
  21. 0:58okay or the enterprise campus
  22. 1:01requirements
  23. 1:02now as shown here in the table
  24. 1:05so each enterprise campus module has
  25. 1:08different requirements
  26. 1:10okay so for example this table
  27. 1:12illustrates
  28. 1:13how modules located closer to user
  29. 1:16require
  30. 1:17a higher degree of scalability so that
  31. 1:20the campus network can be expanded in
  32. 1:22the future
  33. 1:23without redesigning the complete network
  34. 1:27so for example adding new workstations
  35. 1:31to a network should result in a neither
  36. 1:35high investment cost nor performance
  37. 1:39degradation so you've got
  38. 1:42end users in the building access layer
  39. 1:44usually do not require
  40. 1:46high performance or high availability
  41. 1:49but
  42. 1:50these features are crucial to the campus
  43. 1:53core layer
  44. 1:54and the server farm module
  45. 1:58now for the price okay
  46. 2:01the price per port increases with
  47. 2:04increased performance
  48. 2:05and availability now for the campus and
  49. 2:09core
  50. 2:11okay so it requires a guarantee
  51. 2:15of higher throughput so that they can
  52. 2:18handle all traffic flows
  53. 2:20and not introduce additional delays or
  54. 2:23drops
  55. 2:24to the network traffic the edge
  56. 2:27distribution this does not require the
  57. 2:30same performance
  58. 2:32as in the campus core okay so however
  59. 2:36it can require other requirements or
  60. 2:38features and functionalities that
  61. 2:40increase
  62. 2:41the overall cost
  63. 2:43[Music]
  64. 2:47building access layer design
  65. 2:48considerations so when
  66. 2:50implementing the campus infrastructures
  67. 2:53building access layer
  68. 2:54you have to consider the following
  69. 2:56questions okay
  70. 2:58so how many users or host ports
  71. 3:01are currently required in the wiring
  72. 3:03closure
  73. 3:04and how many will it require in the
  74. 3:07future
  75. 3:09so our question would be should the
  76. 3:11switches be
  77. 3:12fixed or modular configuration
  78. 3:15okay so next would be how many ports
  79. 3:20okay so we're talking about the number
  80. 3:21of ports how many ports are available
  81. 3:25for end users connectivity at the walls
  82. 3:28of the building okay how many access
  83. 3:32switches
  84. 3:33are not located in the wiring closets
  85. 3:37what cabling is currently available in
  86. 3:39the wiring closet and
  87. 3:40what cabling options exists for opting
  88. 3:44connectivity so
  89. 3:47others would be what data link layer
  90. 3:49performance
  91. 3:50does the node need what level
  92. 3:53of redundancy is needed okay so we have
  93. 3:56performance redundancy the cabling
  94. 3:59all right so you also have the
  95. 4:03what is the required link capacity to
  96. 4:06the building distribution layer switches
  97. 4:09okay and how will vlans and sdp be
  98. 4:13deployed so take note
  99. 4:15that modern day designs supports
  100. 4:18vlan or the virtual lan and of course
  101. 4:21you also have the spanning tree
  102. 4:24implementation or deployment okay so
  103. 4:28will there be a single vlan or several
  104. 4:30vlans per access switch
  105. 4:33or will the vlans on the switch be
  106. 4:34unique or spread across multiple
  107. 4:36switches
  108. 4:38okay so the latter design was common
  109. 4:42a few years ago but today end-to-end
  110. 4:44villains
  111. 4:46also called as the campus-wide villains
  112. 4:48are not desirable
  113. 4:50okay so our additional features such as
  114. 4:54port security multicast traffic
  115. 4:58the quality of service are disrequired
  116. 5:02okay now based on the answers of those
  117. 5:05questions
  118. 5:06select the devices that satisfies the
  119. 5:09building access layer requirements
  120. 5:11okay now the building access layer
  121. 5:15should maintain the simplicity of
  122. 5:16traditional land switching
  123. 5:18with the support of basic network
  124. 5:21intelligence services
  125. 5:23and business applications
  126. 5:28now what's the key point here okay so
  127. 5:31the following are the best practice
  128. 5:33recommendations for optimal building
  129. 5:35access layer design
  130. 5:37okay so first you have to manage vlan
  131. 5:40and stp okay so with that you have to
  132. 5:44limit valence to a single close-up
  133. 5:45whenever possible
  134. 5:48so if stp is required then it is
  135. 5:50recommended to use
  136. 5:53the rp bsd plus
  137. 5:56next would be you need to set the trunk
  138. 5:59to desirable
  139. 6:01and desirable with negotiate
  140. 6:04okay so if you want to learn more about
  141. 6:07vlans
  142. 6:07so you could go ahead and check the
  143. 6:09supplementary videos
  144. 6:11now manually prone unused vlans is also
  145. 6:15required and then use vtp
  146. 6:19transparent mode so all of this
  147. 6:22recovered on our supplementary video so
  148. 6:25you could check that out
  149. 6:27next would be manage trunk between
  150. 6:29switches
  151. 6:32manage default php or the
  152. 6:35port aggregation protocol settings
  153. 6:38okay and of course you have to consider
  154. 6:40implementing
  155. 6:41routing in the access layer
  156. 6:47now for the stp consideration avoid
  157. 6:50using
  158. 6:50stp if possible okay
  159. 6:54so stp is defined in ieee 802.1d
  160. 6:59avoid requiring any type of stp or
  161. 7:02including
  162. 7:03rapid stp okay so or the rstp
  163. 7:06by design for most deterministic
  164. 7:09and highly available network topology
  165. 7:12that is predictable
  166. 7:13and bounded and has reliably
  167. 7:16tuned convergence so for example
  168. 7:20the behavior of layer 2 environments
  169. 7:23using stp and layer 3 environments using
  170. 7:26a routing protocol are different
  171. 7:28under soft failure conditions
  172. 7:31so when keep alive messages are lost
  173. 7:33okay
  174. 7:34so in sdp environment if
  175. 7:37bridge protocol data units or bpdu are
  176. 7:39lost
  177. 7:40the network fails in an open state
  178. 7:44for wiring traffic with unknown
  179. 7:46destinations on all ports
  180. 7:48potentially causing broadcast storms so
  181. 7:51in contrast
  182. 7:52routing environment fill closed
  183. 7:56dropping routing neighbor relationships
  184. 7:58breaking connectivity and isolating the
  185. 8:00soft
  186. 8:01field devices so another reason
  187. 8:05to avoid using stp is for load balancing
  188. 8:08if there are two redundant links stp by
  189. 8:11default uses only one of these links
  190. 8:13take note
  191. 8:14okay so while routing protocols by
  192. 8:16default uses
  193. 8:18both right
  194. 8:21so what if sdp is required
  195. 8:24okay so if stp is required
  196. 8:29then use rstp with per vlan spanning
  197. 8:33three
  198. 8:33plus okay now if you are using cisco
  199. 8:36devices
  200. 8:37the cisco rp vst plus implementation is
  201. 8:40far superior to 802.1 dstp
  202. 8:45and even the pbsd plus that is
  203. 8:48we're talking about the convergence
  204. 8:50perspective
  205. 8:51okay so it greatly improves the
  206. 8:54performance
  207. 8:55because the convergent times for any
  208. 8:58vlan
  209. 8:59on which a link comes up and it greatly
  210. 9:02improves
  211. 9:03the convergence time compared to
  212. 9:05backbone fast
  213. 9:06okay now another thing is
  214. 9:10you might want to consider the spanning
  215. 9:12tree toolkit
  216. 9:13or the cisco stp toolkit okay
  217. 9:16so those were mentioned in the previous
  218. 9:18video you still remember the term like
  219. 9:20port fast
  220. 9:22okay under port pass you've got a bpdu
  221. 9:24guard vpdu filtering
  222. 9:27okay uplink fast backbone fast stp loop
  223. 9:30guard
  224. 9:30root guard you've got the pptu skew
  225. 9:34detection
  226. 9:35and of course the udld or the
  227. 9:37unidirectional link detection
  228. 9:42now for those cisco stp toolkit
  229. 9:45okay so you've got broadcast so bypass
  230. 9:48listening learning
  231. 9:50okay so for access port so uplink passed
  232. 9:54three to five seconds convergence after
  233. 9:56link failure
  234. 9:57back on fast that's convergence by
  235. 10:01maximum age for indirect failure so some
  236. 10:04of this
  237. 10:05are not anymore supported okay so but
  238. 10:08then portfast
  239. 10:10okay look guard root guard those are
  240. 10:13still active
  241. 10:14okay now for the loop guard it prevents
  242. 10:18alternate or root port from becoming a
  243. 10:20designated
  244. 10:22in the absence of the ppd use
  245. 10:25now root guard prevents external
  246. 10:27switches from becoming a root
  247. 10:30and vpdu guard it disables the port fast
  248. 10:34enabled port
  249. 10:35if bpdu is received so if you want to
  250. 10:38learn
  251. 10:39more about this cisco stp toolkit again
  252. 10:43try to visit our supplementary videos
  253. 10:52trunk considerations so managing trunks
  254. 10:56between switches so trunks are typically
  255. 11:00deployed
  256. 11:01on the interconnection between the
  257. 11:03building access and the building
  258. 11:05distribution layers
  259. 11:07so there are several best practices to
  260. 11:10implement
  261. 11:11with regard to trunking okay
  262. 11:14so you have to consider the trunk
  263. 11:17mode and encapsulation
  264. 11:21so as a best practice when configuring
  265. 11:24trunks
  266. 11:25set the dynamic trunking protocol or
  267. 11:28dtp to desirable
  268. 11:31on one side and of course desirable on
  269. 11:34the other end
  270. 11:35so with that is a negotiation option
  271. 11:38so one side would be undesirable
  272. 11:42okay so to have the negotiation between
  273. 11:44the switch
  274. 11:46okay so you could also set the pruning
  275. 11:49okay or manually pruning vlans another
  276. 11:52best practice
  277. 11:53is to manually prune unused vlans from
  278. 11:56trunk interfaces
  279. 11:58to avoid broadcast propagation
  280. 12:02so cisco recommends not using automatic
  281. 12:05vlan pruning
  282. 12:06manual pruning provides air control
  283. 12:11so as mentioned the campus wide or
  284. 12:14access layer wide
  285. 12:15vlans are no longer recommended so vlan
  286. 12:18pruning is less of an
  287. 12:19issue than it is used to be
  288. 12:24next would be the btp transparent mode
  289. 12:29so vtp transparent mode should be used
  290. 12:32as
  291. 12:32best practice because hierarchical
  292. 12:35network have
  293. 12:36little need for a shared common vlan
  294. 12:38database
  295. 12:40so using vtp transparent mode decreases
  296. 12:42the potential for operational errors
  297. 12:46okay next would be trunking on ports
  298. 12:50so trunking should be disabled on
  299. 12:53ports to which hosts will be attached
  300. 12:56so that host devices do not need to
  301. 12:58negotiate
  302. 12:59trunk status so this best practice
  303. 13:03okay it speeds up the port passed
  304. 13:07and is a security measure to prevent
  305. 13:09villain happening
  306. 13:14layer 3 access the distribution
  307. 13:16interconnection
  308. 13:18okay so take note from the hierarchy
  309. 13:21you've got the access this is where the
  310. 13:23users are connected to
  311. 13:24and then of course you'll have
  312. 13:25distribution devices
  313. 13:28so although it is not widely deployed in
  314. 13:30the building access layer
  315. 13:32a routing protocol such as eigrp
  316. 13:35or ospf when properly tuned
  317. 13:38can achieve better convergence results
  318. 13:41than layer 2 and layer 3 boundary
  319. 13:42hierarchical design
  320. 13:44that relies on sdp okay now however
  321. 13:49adding routing does not result in some
  322. 13:51additional complexities
  323. 13:53including uplink ip addressing and
  324. 13:54subnetting and loss of
  325. 13:57flexibility okay now this figure here
  326. 14:00illustrates a sample network with layer
  327. 14:033 routing
  328. 14:04okay and that is basically
  329. 14:09on both the axis
  330. 14:12and the distribution layer okay now in
  331. 14:15this figure
  332. 14:16equal cost layer 3 load balancing is
  333. 14:19performed on all links
  334. 14:21although eigrp could perform
  335. 14:24an equal cost load balancing
  336. 14:27so stp is not running and the first top
  337. 14:31redundancy protocol such as
  338. 14:34hsrp or the hot standby
  339. 14:37router protocol is not required
  340. 14:41so vlan cannot
  341. 14:44span across the multi-layer switch
  342. 14:48so no vlan spanning is possible
  343. 14:54building distribution layer design
  344. 14:56consideration
  345. 14:58now the building distribution layer
  346. 15:00aggregates the building access
  347. 15:03okay segment work groups and isolate
  348. 15:06segments from failures
  349. 15:07and broadcast storms so this layer
  350. 15:11implements many policies based on the
  351. 15:14access lists
  352. 15:15and quality of service settings so the
  353. 15:19building distribution layer can protect
  354. 15:21the campus core network from any impact
  355. 15:24of building access layer problems
  356. 15:27by implementing all the organizations
  357. 15:30policies
  358. 15:32so when implementing organization
  359. 15:35policies
  360. 15:36okay so the building distribution layer
  361. 15:38considered
  362. 15:40the following questions so something
  363. 15:42like
  364. 15:43how many devices will each building
  365. 15:46distribution switch
  366. 15:47handle so other questions
  367. 15:51uh what type and level of redundancy are
  368. 15:54required
  369. 15:55how many uplinks are needed what speed
  370. 15:58do the uplinks need
  371. 16:01to be to the building core switches
  372. 16:04what cabling is currently available in
  373. 16:07the wiring closet
  374. 16:08and what cabling options exists for
  375. 16:11uplink connectivity
  376. 16:13okay so as network services are
  377. 16:15introduced
  378. 16:17it can it can continue to deliver high
  379. 16:20performance
  380. 16:21okay so for all its applications such as
  381. 16:23the video on demand
  382. 16:25ip multicast or ip telephony
  383. 16:29so the network designer must pay special
  384. 16:33attention to the following network
  385. 16:34characteristics here
  386. 16:35so first is of course performance so
  387. 16:38building distribution switches should
  388. 16:40provide
  389. 16:41a wire speed performance on all ports
  390. 16:44so this feature is important because of
  391. 16:47the building access layer aggregation
  392. 16:49on one side and high speed connectivity
  393. 16:52to the compass core module
  394. 16:53on the other side so future expansions
  395. 16:56with additional ports or modules can
  396. 16:59result in an
  397. 17:00overloaded switch if it is not selected
  398. 17:03properly
  399. 17:04so another consideration would be the
  400. 17:08redundancy
  401. 17:09okay redundancy or redundant building
  402. 17:12distribution layer switches and
  403. 17:13redundant connections to the campus core
  404. 17:16should be implemented so using
  405. 17:19equal cost redundant connections to the
  406. 17:21core supports
  407. 17:22fast convergence and avoids routing
  408. 17:26black holes
  409. 17:27so network bandwidth and capacity should
  410. 17:30be engineered
  411. 17:32to withstand node or link failure
  412. 17:36and the last one would be the
  413. 17:38infrastructure services
  414. 17:40so building distribution switches should
  415. 17:42not only support
  416. 17:44past multi-layer switching but
  417. 17:48also incorporate network services
  418. 17:52such as high availability quality of
  419. 17:55service
  420. 17:56security and policy enforcement
  421. 17:59so expanding and order reconfiguring
  422. 18:02distribution layer devices
  423. 18:04must be easy and efficient so these
  424. 18:07devices must support the required
  425. 18:10management feature
  426. 18:16overview of recommended uh practices for
  427. 18:19building distribution layer
  428. 18:21so the key point here is the following
  429. 18:24are the best practice recommendations
  430. 18:26for optimal building distribution layer
  431. 18:28design
  432. 18:29so first you have to use the first half
  433. 18:31redundancy protocol
  434. 18:33okay so either you use the hsrp
  435. 18:37glb or the brrp
  436. 18:40next would be deploy a layer 3 routing
  437. 18:43protocols between the building
  438. 18:44distribution switches
  439. 18:46and campus core switches
  440. 18:50okay and last would be if required
  441. 18:54connect the distribution switches
  442. 18:57okay so
  443. 19:00that is it should be connected to
  444. 19:02support layer to vlan spanning multiple
  445. 19:05access switches
  446. 19:06okay so if required building
  447. 19:09distribution switches should support
  448. 19:10vlans that span multiple building access
  449. 19:14layer switches
  450. 19:19so using the first half redundancy
  451. 19:21protocol
  452. 19:23so if layer 2 is used
  453. 19:26between the building access and the
  454. 19:28building distribution switches
  455. 19:31convergence time when a link or node
  456. 19:34fails depends on the default gateway
  457. 19:36redundancy and fill over time
  458. 19:38okay so building distribution switches
  459. 19:41typically provide
  460. 19:42high or the first half redundancy which
  461. 19:45is the default gateway redundancy using
  462. 19:47either
  463. 19:48hsrp okay or you also have the glbp or
  464. 19:53the
  465. 19:54gateway load balancing protocol and
  466. 19:57vrrp or the virtual router redundancy
  467. 20:00protocol
  468. 20:02so this redundancy allows a network to
  469. 20:04recover from the failure
  470. 20:06of the device acting as a default
  471. 20:08gateway for end nodes
  472. 20:11on a physical segment okay
  473. 20:15so uplink tracking should also be
  474. 20:17implemented with a first half redundancy
  475. 20:19protocol
  476. 20:20so basically hsrp vrrp and glb all of
  477. 20:25those
  478. 20:25are classified to be in the first half
  479. 20:28redundancy protocol
  480. 20:30okay so hsrp or glb timers can
  481. 20:35reliably tuned to achieve a sub second
  482. 20:38800 to 900 milliseconds
  483. 20:42so we're talking about convergence for
  484. 20:44link
  485. 20:45or node failure in the boundary between
  486. 20:48layer 2 and layer 3 in the building
  487. 20:49distribution layer
  488. 20:55now how about the recommended practices
  489. 20:58on the use of layer 3 routing protocols
  490. 21:01okay so deploying a layer 3 routing
  491. 21:04protocols between building distribution
  492. 21:06and campus core switches
  493. 21:08so routing protocols between the
  494. 21:10building distribution switches
  495. 21:12and the campus scores which support past
  496. 21:15deterministic convergence for the
  497. 21:18distribution layer across redundant
  498. 21:19things
  499. 21:21so convergence based on the up or down
  500. 21:24state
  501. 21:26of a point-to-point physical link is
  502. 21:28faster than
  503. 21:29timer based non-deterministic
  504. 21:31convergence
  505. 21:33so instead of indirect neighbor or route
  506. 21:36loss detection using hellos
  507. 21:38and that so physical link loss
  508. 21:41indicates that a pass is unusable
  509. 21:46so that means all traffic is routed
  510. 21:50to the alternative equal cost path
  511. 21:57okay so build redundant triangle
  512. 22:00okay so what do we mean by this
  513. 22:01redundant triangle so i'll have this
  514. 22:03okay so not the square so for optimum
  515. 22:07distribution to core layer convergence
  516. 22:10build redundant triangle not squares
  517. 22:13that is to take advantage of the equal
  518. 22:15cost redundant path
  519. 22:17for the best deterministic convergence
  520. 22:20so figure four
  521. 22:22okay our figure model a and figure model
  522. 22:25b
  523. 22:26here illustrates the difference okay
  524. 22:29now on the left okay or
  525. 22:32on the model a the multi-layer switches
  526. 22:35are connected redundantly with a
  527. 22:38triangle
  528. 22:39of links that have layer three equal
  529. 22:42cost paths
  530. 22:43okay now because the links have equal
  531. 22:46costs
  532. 22:47they appear in the routing table and by
  533. 22:49default
  534. 22:50will be used for load balancing so
  535. 22:53if one of the links or distribution
  536. 22:55layer devices fails
  537. 22:56convergence is extremely fast
  538. 23:00because the failure is detected in
  539. 23:01hardware and there is no need for the
  540. 23:03routing protocol to recalculate a new
  541. 23:05path
  542. 23:07so it just continues to use one of the
  543. 23:10paths
  544. 23:11already in its routing table so in
  545. 23:13contrast
  546. 23:15on this diagram here okay model b
  547. 23:18only one path is active by default
  548. 23:22and link or device failure requires the
  549. 23:24routing protocol to recalculate a new
  550. 23:26route
  551. 23:27to convergence
  552. 23:32layer 3 distribution interconnection
  553. 23:35so in cisco deployments hsrp is
  554. 23:38typically used as the default gateway
  555. 23:40redundancy protocol
  556. 23:42so vrrp is an internet engineering task
  557. 23:46force or ietf standards
  558. 23:48based method of providing
  559. 23:51default gateway redundancy so if you are
  560. 23:53using non-cisco devices then you could
  561. 23:55go ahead and
  562. 23:56use vrrp instead so
  563. 24:00more deployments are starting to use the
  564. 24:02glbp because
  565. 24:04it supports load balancing on the
  566. 24:06uplinks
  567. 24:07from the access layer to the
  568. 24:09distribution layer
  569. 24:11okay as well as the first half
  570. 24:14redundancy and failure protection
  571. 24:17now on this diagram here this model
  572. 24:20supports
  573. 24:21a recommended layer three point to point
  574. 24:24interconnection between the distribution
  575. 24:26and the access switches
  576. 24:29so no vlan span the building access
  577. 24:32layer switches
  578. 24:33across the distribution okay
  579. 24:36so from an stp perspective
  580. 24:39both access layer uplinks and forwarding
  581. 24:42and no sd convergence is required if
  582. 24:44uplink failure occurs
  583. 24:47all right so the only convergence
  584. 24:50dependencies are the default gateway
  585. 24:53and return path route selection across
  586. 24:56layer 3 distribution
  587. 24:58to distribution link okay
  588. 25:02so if layer 3 is used to the building
  589. 25:05access switch the default gateway
  590. 25:07is at the multi-layer building access
  591. 25:10switch
  592. 25:11and a first half redundancy protocol is
  593. 25:13not needed
  594. 25:16so if you want to learn more about this
  595. 25:18redundancy
  596. 25:19okay so you could check these
  597. 25:21supplementary videos
  598. 25:23okay so topics about fhrp okay
  599. 25:28that includes hsrp brp
  600. 25:32glb all under the first half redundancy
  601. 25:36protocol or the fhrp
  602. 25:42so layer two distribution
  603. 25:43interconnection so let's have this
  604. 25:45alternate here supporting vlans that
  605. 25:47span multiple building access layer
  606. 25:48switches
  607. 25:50so in less than optimal design where
  608. 25:52vlans span multiple building
  609. 25:55okay the building distribution switches
  610. 25:58must be linked
  611. 25:59by a layer to connection or
  612. 26:02the building access layer switches must
  613. 26:04be connected via
  614. 26:05trunks okay so trunks should be enabled
  615. 26:09only between switches okay
  616. 26:13now this design is more complex than
  617. 26:16when the building distribution switches
  618. 26:18are interconnected with
  619. 26:19layer 3 okay so
  620. 26:22sdp convergence is required if an uplink
  621. 26:26failure occurs so again
  622. 26:29as shown in this figure the following
  623. 26:31are the recommendations for use
  624. 26:34in the sub-optimal design okay so use
  625. 26:38rp bsd plus as a version of stp
  626. 26:43right so provide a layer to link between
  627. 26:47the two building distribution switches
  628. 26:50okay so that is to avoid unexpected
  629. 26:52traffic pass and multiple convergence
  630. 26:54events
  631. 26:55so if you choose the load balancing okay
  632. 27:00be sure to place the hsrp between the
  633. 27:05or the hsrp primary and the pvsd
  634. 27:08plus root on the same building
  635. 27:10distribution layer
  636. 27:12to avoid using inter distribution switch
  637. 27:15link
  638. 27:15for transit
  639. 27:21campus core design consideration
  640. 27:25so first low price okay
  641. 27:28low price per port and high port density
  642. 27:31can govern switch choice for wiring
  643. 27:34closet environments
  644. 27:36but high performance wire rate
  645. 27:39multi-layer switching drives the campus
  646. 27:41core design
  647. 27:43so using the campus core switches
  648. 27:45reduces the number of connections
  649. 27:46between the building distribution layer
  650. 27:48switches
  651. 27:49and simplifies the integration of the
  652. 27:51server farm
  653. 27:53and the enterprise edge modules
  654. 27:56okay now the compass core switches
  655. 28:00are primarily focused on wire speed
  656. 28:03forwarding
  657. 28:04on all the interfaces and are
  658. 28:06differentiated by the level of
  659. 28:07performance achieved
  660. 28:09per port rather than high port
  661. 28:12densities so what's the key point here
  662. 28:16as recommended practice deploy a
  663. 28:19dedicated campus core
  664. 28:21layer that is to connect three or more
  665. 28:25buildings
  666. 28:26and the enterprise campus okay
  667. 28:30so compost core switches are typically
  668. 28:33multi-layer switches or layer 3 switches
  669. 28:36so using a campus core makes scaling the
  670. 28:39network easier
  671. 28:41for example with the campus core
  672. 28:45new building distribution switches only
  673. 28:48need connectivity to the core
  674. 28:50rather than full mesh connectivity to
  675. 28:52all other building distribution switches
  676. 28:56okay
  677. 29:01about large campus multi-layer switch
  678. 29:04backbone design
  679. 29:05so we're talking about the compost or
  680. 29:07large campus design here
  681. 29:09so for large campus the most
  682. 29:12flexible and scalable compass core layer
  683. 29:15consists of dual multi-layer switches
  684. 29:18as illustrated on this diagram here okay
  685. 29:22so you've got the reduced multi-layer
  686. 29:24switch
  687. 29:26gearing or routing adjacencies
  688. 29:29so each multi-layer building
  689. 29:32distribution switch connects to only two
  690. 29:34multi-layer campus core switches
  691. 29:37so using a redundant triangle
  692. 29:39configuration as shown earlier
  693. 29:42this implementation simplifies any to
  694. 29:45any connectivity between building
  695. 29:46distribution
  696. 29:48and campus core switches and is scalable
  697. 29:51to an arbitrarily large size
  698. 29:54it also supports redundancy and load
  699. 29:57sharing so next would be
  700. 30:01topology with no spanning three loops
  701. 30:04so no stp activity exists in the compass
  702. 30:08core or on the building distribution
  703. 30:10links to the campus core layer
  704. 30:13because all the links are layer 3 or
  705. 30:15routed links
  706. 30:16so arbitrary topologies are supported by
  707. 30:19the routing protocol used
  708. 30:20in the campus correlator because the
  709. 30:23core is
  710. 30:23routed it also provides multicast and
  711. 30:26broadcast
  712. 30:28control so next one would be
  713. 30:32improved network services support so
  714. 30:35multi-layered campus core switches
  715. 30:37provide
  716. 30:38better support for intelligent network
  717. 30:41services
  718. 30:42than data link layer core switches could
  719. 30:44support
  720. 30:45okay now this design maintains two equal
  721. 30:49cost
  722. 30:50paths to every destination network so
  723. 30:52thus recovery from any link failure is
  724. 30:55fast
  725. 30:56and load sharing is possible
  726. 30:59okay so resulting to a higher throughput
  727. 31:03in the compass core layer
  728. 31:05so one of the main considerations when
  729. 31:07using multi-layer switches
  730. 31:08in the campus core is switching
  731. 31:10performance
  732. 31:12okay multi-layer switching requires more
  733. 31:14sophisticated devices
  734. 31:16for high speed packet routing
  735. 31:19so modern layer 3 switches support
  736. 31:22routing in the hardware
  737. 31:24even though the hardware might not
  738. 31:25support all the features
  739. 31:28so if the hardware does not support a
  740. 31:29selected feature
  741. 31:31it must be performed in software
  742. 31:35this can dramatically reduce data
  743. 31:37transfer
  744. 31:38okay so for example access list
  745. 31:41might not be processed in the hardware
  746. 31:44if they have too many
  747. 31:45entries resulting in switch performance
  748. 31:48degradation
  749. 31:54small and medium campus design options
  750. 31:58so a small campus or large branch
  751. 32:01network might have fewer than 210
  752. 32:03devices
  753. 32:04and network servers and workstations
  754. 32:06might be connected to the same wiring
  755. 32:08closet
  756. 32:09or telecommunication closet now because
  757. 32:12switches in a small campus network
  758. 32:14design may not require
  759. 32:15high-end switching performance or much
  760. 32:18scaling capability in many cases
  761. 32:21the campus core and building
  762. 32:22distribution layers can be combined into
  763. 32:24a single layer
  764. 32:25as illustrated on this diagram here
  765. 32:28okay so this is building access
  766. 32:31switching
  767. 32:34all right so this design can scale to
  768. 32:37only few building access layer switches
  769. 32:40a low-end multi-layer switch provides
  770. 32:43routing services
  771. 32:44closer to the end user when multiple
  772. 32:47vlans exist
  773. 32:50so for a very small office
  774. 32:53only low-end multi-layer switch may
  775. 32:55support
  776. 32:56the lan access requirements for the
  777. 32:59entire office
  778. 33:01okay so for a medium-sized campus with
  779. 33:04200
  780. 33:05to 1000 end devices the network
  781. 33:08infrastructure typically consists of
  782. 33:10building access layers such as
  783. 33:12with uplinks to building distribution or
  784. 33:14campus core multi-layer switches
  785. 33:16that can support the performance
  786. 33:18requirements of a medium-sized campus
  787. 33:21network
  788. 33:23so if redundancy is required
  789. 33:27redundant multi-layer switches connect
  790. 33:30to
  791. 33:30or connected to the building axis
  792. 33:32switches providing full link redundancy
  793. 33:36as shown here in the diagram okay so
  794. 33:39when
  795. 33:39when one of this devices here goes down
  796. 33:43so there is still a connectivity going
  797. 33:45to your server form
  798. 33:49edge distribution design so let's talk
  799. 33:53about the edge distribution at the
  800. 33:54campus core
  801. 33:56so as mentioned in the previous video
  802. 33:58the enterprise edge
  803. 33:59modules connect to the campus core
  804. 34:01directly
  805. 34:02or through an optional edge distribution
  806. 34:06module
  807. 34:07okay now the edge distribution
  808. 34:11multi-layer switches filter
  809. 34:13and route traffic into the compass core
  810. 34:16aggregate enterprise edge connectivity
  811. 34:20and provide advanced services
  812. 34:24so switching speed is not as important
  813. 34:27as security
  814. 34:28in the edge distribution module which
  815. 34:31isolates and controls
  816. 34:33access to devices that are located
  817. 34:36in the enterprise edge module for
  818. 34:38example
  819. 34:39servers in an e-commerce okay
  820. 34:42or public servers in an internet
  821. 34:44connectivity module
  822. 34:46so this servers are closer to the
  823. 34:49external users and therefore introduce
  824. 34:51a higher risk to the internal campus
  825. 34:55so to protect the campus core
  826. 34:58from threats the switches in the edge
  827. 35:02distribution module must protect the
  828. 35:03compass from
  829. 35:05any of the following attacks okay like
  830. 35:08an authorized access all connections
  831. 35:11from the edge distribution module that
  832. 35:14pass through the campus core
  833. 35:16must be verified against the user
  834. 35:19and the user's rights okay
  835. 35:23you also have ip spoofing so ip spoofing
  836. 35:27is a hacker technique for
  837. 35:28impersonating the identity of another
  838. 35:30user
  839. 35:32by using the user's ip address
  840. 35:35so denial of service or dos attacks use
  841. 35:38ib spoofing
  842. 35:39to generate requests to servers using
  843. 35:42the stolen ip address as a source
  844. 35:46you also have this network
  845. 35:48reconnaissance
  846. 35:50what is reconnaissance reconnaissance
  847. 35:52means
  848. 35:53discovery okay so
  849. 35:56the network reconnaissance or discovery
  850. 35:58sends packets
  851. 36:00into the network and collects responses
  852. 36:03from the network devices so these
  853. 36:06responses provide basic information
  854. 36:09about internal network topology
  855. 36:13so next would be packet sniffers
  856. 36:16so packet sniffers are devices that
  857. 36:18monitor and capture the traffic in the
  858. 36:20network
  859. 36:21and might be used by hackers so packets
  860. 36:25belonging to
  861. 36:27the same broadcast domain are vulnerable
  862. 36:30to capture
  863. 36:30by pocket sniffers okay especially if
  864. 36:34the packets are broadcast or
  865. 36:38multicast
  866. 36:41server placement in a medium-sized
  867. 36:43network
  868. 36:45so within the campus network servers may
  869. 36:47be placed
  870. 36:48locally in the building access or
  871. 36:50building distribution layer
  872. 36:52or attach directly to the campus core
  873. 36:56now centralized servers are typically
  874. 36:58grouped into a server farm
  875. 37:01located in the enterprise campus or in a
  876. 37:04separate data center
  877. 37:07so servers directly attached to building
  878. 37:10access or building distribution layer
  879. 37:12switches
  880. 37:15so if a server is local to a certain
  881. 37:18work group
  882. 37:19okay that corresponds to one vlan
  883. 37:22and all workgroup members and the server
  884. 37:25are attached to the building access
  885. 37:27layer switch
  886. 37:28most of the traffic to the server is
  887. 37:30local to the workgroup
  888. 37:32so if required an access list at the
  889. 37:36building distribution layer switch
  890. 37:38would hide the servers from the
  891. 37:40enterprise
  892. 37:41so in some mid-size networks building
  893. 37:45level servers that communicate with
  894. 37:47clients in different vlans
  895. 37:50but that are still within the same
  896. 37:52physical building
  897. 37:54can be connected to building
  898. 37:56distribution layer switches
  899. 37:58okay so how about servers directly
  900. 38:02connected to the campus core
  901. 38:04is that possible well you can do that
  902. 38:07okay
  903. 38:07so the campus core generally transports
  904. 38:10traffic quickly without any limitations
  905. 38:14so servers in the medium-sized campus
  906. 38:17can be connected directly to the campus
  907. 38:19core switches
  908. 38:21okay so making the servers closer to the
  909. 38:23users
  910. 38:25than if the servers were in the server
  911. 38:27form
  912. 38:28as shown here in the future
  913. 38:32now however ports are typically limited
  914. 38:35in the campus core switches
  915. 38:37so policy based control qos and access
  916. 38:40control list or acl
  917. 38:42for accessing the servers is implemented
  918. 38:44in the building distribution layer
  919. 38:46rather than in the campus core
  920. 38:52how about server placement in a large
  921. 38:54network
  922. 38:55okay servers in the server farm module
  923. 38:59so larger enterprises may have
  924. 39:03moderate or large server deployments
  925. 39:06for enterprises with
  926. 39:09moderate server requirements common
  927. 39:12servers are located in a separate server
  928. 39:14form module connected to the compass
  929. 39:16core
  930. 39:17using a multi-layer server distribution
  931. 39:20switches
  932. 39:22okay now because of a high traffic load
  933. 39:26the servers are usually gigabit ethernet
  934. 39:29attached to the server farm switches
  935. 39:33so access list on the server farm module
  936. 39:37okay so implements the controlled access
  937. 39:39to the servers
  938. 39:41redundant distribution switches in the
  939. 39:43server farm module
  940. 39:45and solutions such as the hsrp or glb
  941. 39:48provides
  942. 39:50fast failover so the server farm module
  943. 39:54distribution switches
  944. 39:56also keep all the server to
  945. 39:59server traffic of the campus core
  946. 40:05all right so how about the server farm
  947. 40:07design guidelines
  948. 40:09okay so as shown here in the figure
  949. 40:12the server form can be implemented as
  950. 40:16high capacity building block attached to
  951. 40:18the campus core
  952. 40:19so again you have redundancy of
  953. 40:21connectivity there okay
  954. 40:25now one of the main concerns with the
  955. 40:27server farm module
  956. 40:29is that it receives the majority of the
  957. 40:31traffic from the entire campus
  958. 40:34so random frame drops can result because
  959. 40:38the uplinks ports on the switches
  960. 40:41are frequently over subscribed okay
  961. 40:44so when say switch over subscription it
  962. 40:47of course when a switch allows
  963. 40:49more ports or bandwidth in the chassis
  964. 40:52then switch hardware can transfer
  965. 40:54through its internal structure
  966. 40:57right so to guarantee that no random
  967. 41:01frame jobs occur for business critical
  968. 41:03applications
  969. 41:04the network designer should apply the
  970. 41:06quality of service mechanisms
  971. 41:09okay now next would be
  972. 41:14the server connectivity options
  973. 41:17so servers can be connected in several
  974. 41:20different ways for example
  975. 41:22a server farm or a server can attach
  976. 41:26by one or two fast ethernet connections
  977. 41:30okay so that's dual and ic redundancy
  978. 41:34so if the server is dual attached okay
  979. 41:37or dual nic redundancy
  980. 41:39one interface can be active while the
  981. 41:41other is
  982. 41:42in hot standby
  983. 41:45now installing multiple single port nic
  984. 41:48or multi-port and ics
  985. 41:50in the servers extends dual home
  986. 41:52rehoming passed
  987. 41:54the server farm okay so to the server
  988. 41:57itself
  989. 41:58so servers needing redundancy can be
  990. 42:02connected with
  991. 42:03dual and ic homing in the access layer
  992. 42:06or at
  993. 42:07an nic that supports easter channel okay
  994. 42:11well several other solutions are
  995. 42:12available
  996. 42:14to improve server responsiveness
  997. 42:17and evenly distribute the load to them
  998. 42:19so we call it
  999. 42:20load balancing right so that
  1000. 42:23is we have to use okay so our
  1001. 42:27redundant link also to move the data
  1002. 42:30from the source to destination
  1003. 42:32not just using it for backups
  1004. 42:38now to summarize the enterprise campus
  1005. 42:40design
  1006. 42:42design and enterprise campus network
  1007. 42:44using recommended processes
  1008. 42:46so use low price per port
  1009. 42:49and high port density on data link layer
  1010. 42:53switches
  1011. 42:54for building the access layer
  1012. 42:57use redundant multi-layer switching in
  1013. 43:00the building distribution layer
  1014. 43:02for high availability and performance
  1015. 43:06use high performance wire rate
  1016. 43:09multi-layer switching in the compass
  1017. 43:11core design
  1018. 43:12and group centralized servers into
  1019. 43:15server form module
  1020. 43:16for moderate enterprise server
  1021. 43:22requirements

About this transcript

This page contains the full transcript of Designing Basic Enterprise Campus Networks Part 2 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 4,905 words across 1,021 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.